{"id":"MGASA-2026-0229","summary":"Updated podofo packages fix security vulnerabilities","details":"Podofo v0.9.8 shares some of the vulnerable code that was discovered in\nPodofo v0.10.0. This package fixes that.\nCVE-2023-31567 Podofo v0.10.0 was discovered to contain a heap buffer\noverflow via the component PoDoFo::PdfEncryptAESV3::PdfEncryptAESV3.\nCVE-2023-31568 Podofo v0.10.0 was discovered to contain a heap buffer\noverflow via the component PoDoFo::PdfEncryptRC4::PdfEncryptRC4.\n","modified":"2026-06-24T05:45:04.583713145Z","published":"2026-06-24T05:41:50Z","upstream":["CVE-2023-31567","CVE-2023-31568"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2026-0229.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=33207"},{"type":"WEB","url":"https://github.com/podofo/podofo/commit/8f514d69b4ac3c9aa9f725fa93486fe4b7876642"},{"type":"WEB","url":"https://lwn.net/Articles/980540/"},{"type":"REPORT","url":"https://github.com/podofo/podofo/issues/71"},{"type":"REPORT","url":"https://github.com/podofo/podofo/issues/72"}],"affected":[{"package":{"name":"podofo","ecosystem":"Mageia:9","purl":"pkg:rpm/mageia/podofo?arch=source&distro=mageia-9"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.9.8-2.1.mga9"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2026-0229.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}